Security And Hardening
penpot/penpot
Hardens code against vulnerabilities. An agent skill from penpot/penpot.
This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks"…
$ npx skills add zebbern/claude-code-guide --skill top-web-vulnerabilities -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install zebbern/claude-code-guide top-web-vulnerabilities --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/top-web-vulnerabilities .claude/skills/top-web-vulnerabilities && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "top-web-vulnerabilities" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/top-web-vulnerabilities into .claude/skills/top-web-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "top-web-vulnerabilities", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/zebbern/claude-code-guide/tree/main/skills/top-web-vulnerabilitiesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add zebbern/claude-code-guide --skill top-web-vulnerabilities -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install zebbern/claude-code-guide top-web-vulnerabilities --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/top-web-vulnerabilities .agents/skills/top-web-vulnerabilities && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "top-web-vulnerabilities" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/top-web-vulnerabilities into .agents/skills/top-web-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "top-web-vulnerabilities", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zebbern/claude-code-guide --skill top-web-vulnerabilities -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install zebbern/claude-code-guide top-web-vulnerabilities --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/top-web-vulnerabilities .cursor/skills/top-web-vulnerabilities && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "top-web-vulnerabilities" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/top-web-vulnerabilities into .cursor/skills/top-web-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "top-web-vulnerabilities", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/zebbern/claude-code-guide.git --path skills/top-web-vulnerabilities--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add zebbern/claude-code-guide --skill top-web-vulnerabilities -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install zebbern/claude-code-guide top-web-vulnerabilities --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/top-web-vulnerabilities .gemini/skills/top-web-vulnerabilities && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "top-web-vulnerabilities" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/top-web-vulnerabilities into .gemini/skills/top-web-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "top-web-vulnerabilities", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install zebbern/claude-code-guide top-web-vulnerabilitiesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add zebbern/claude-code-guide --skill top-web-vulnerabilities -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/top-web-vulnerabilities .github/skills/top-web-vulnerabilities && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "top-web-vulnerabilities" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/top-web-vulnerabilities into .github/skills/top-web-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "top-web-vulnerabilities", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zebbern/claude-code-guide --skill top-web-vulnerabilities -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install zebbern/claude-code-guide top-web-vulnerabilities --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/top-web-vulnerabilities .opencode/skills/top-web-vulnerabilities && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "top-web-vulnerabilities" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/top-web-vulnerabilities into .opencode/skills/top-web-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "top-web-vulnerabilities", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
top-web-vulnerabilitiesThis skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks"…
Top Web Vulnerabilities is an agent skill from zebbern/claude-code-guide. This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks", "review access control weaknesses", "analyze API security issues", "assess security misconfigurations", "understand client-side vulnerabilities", "examine mobile and IoT security flaws", or "reference the OWASP-aligned vulnerability taxonomy". Use this skill to provide comprehensive vulnerability definitions, root…
Its SKILL.md is about 6.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Web application vulnerabilities. The repository describes itself as: Claude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks from beginner to power user! The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e62775c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Top Web Vulnerabilities loads about 6.1k tokens when it runs. Until then it costs about 155 tokens; SKILL.md has 2,585 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from zebbern/claude-code-guide at commit e62775c, republished under its MIT licence (© zebbern). 2,585 words, ~6,064 tokens.
.claude/skills/top-web-vulnerabilities/SKILL.md (or your agent's skills folder).Provide a comprehensive, structured reference for the 100 most critical web application vulnerabilities organized by category. This skill enables systematic vulnerability identification, impact assessment, and remediation guidance across the full spectrum of web security threats. Content organized into 15 major vulnerability categories aligned with industry standards and real-world attack patterns.
Evaluate injection attack vectors targeting data processing components:
SQL Injection (1)
Cross-Site Scripting - XSS (2)
Command Injection (5, 11)
XML Injection (6), LDAP Injection (7), XPath Injection (8)
Server-Side Template Injection - SSTI (13)
Assess authentication mechanism weaknesses:
Session Fixation (14)
Brute Force Attack (15)
Session Hijacking (16)
Credential Stuffing and Reuse (22)
Insecure "Remember Me" Functionality (85)
CAPTCHA Bypass (86)
Identify data protection failures:
IDOR - Insecure Direct Object References (23, 42)
Data Leakage (24)
Unencrypted Data Storage (25)
Information Disclosure (33)
Assess configuration weaknesses:
Missing Security Headers (26)
Default Passwords (28)
Directory Listing (29)
Unprotected API Endpoints (30)
Open Ports and Services (31)
Misconfigured CORS (35)
Unpatched Software (34)
Evaluate XML processing security:
XXE - XML External Entity Injection (37)
XEE - XML Entity Expansion (38)
XML Bomb (Billion Laughs) (39)
XML Denial of Service (65)
Assess authorization enforcement:
Inadequate Authorization (40)
Privilege Escalation (41)
Forceful Browsing (43)
Missing Function-Level Access Control (44)
Evaluate object serialization security:
Remote Code Execution via Deserialization (45)
Data Tampering (46)
Object Injection (47)
Evaluate API-specific vulnerabilities:
Insecure API Endpoints (48)
API Key Exposure (49)
Lack of Rate Limiting (50)
Inadequate Input Validation (51)
API Abuse (75)
Assess transport layer protections:
Man-in-the-Middle Attack (52)
Insufficient Transport Layer Security (53)
Insecure SSL/TLS Configuration (54)
Insecure Communication Protocols (55)
Evaluate browser-side security:
DOM-based XSS (56)
Insecure Cross-Origin Communication (57)
Browser Cache Poisoning (58)
Clickjacking (59, 71)
HTML5 Security Issues (60)
Evaluate availability threats:
DDoS - Distributed Denial of Service (61)
Application Layer DoS (62)
Resource Exhaustion (63)
Slowloris Attack (64)
Assess SSRF vulnerabilities:
SSRF - Server-Side Request Forgery (66)
Blind SSRF (87)
Time-Based Blind SSRF (88)
| # | Vulnerability | Root Cause | Impact | Mitigation |
|---|---|---|---|---|
| 67 | HTTP Parameter Pollution | Inconsistent parsing | Injection, ACL bypass | Strict parsing, validation |
| 68 | Insecure Redirects | Unvalidated targets | Phishing, malware | Whitelist destinations |
| 69 | File Inclusion (LFI/RFI) | Unvalidated paths | Code exec, disclosure | Whitelist files, disable RFI |
| 70 | Security Header Bypass | Misconfigured headers | XSS, clickjacking | Proper headers, audits |
| 72 | Inadequate Session Timeout | Excessive timeouts | Session hijacking | Idle termination, timeouts |
| 73 | Insufficient Logging | Missing infrastructure | Detection gaps | SIEM, alerting |
| 74 | Business Logic Flaws | Insecure design | Fraud, unauthorized ops | Threat modeling, testing |
| # | Vulnerability | Root Cause | Impact | Mitigation |
|---|---|---|---|---|
| 76 | Insecure Mobile Storage | Plain text, weak crypto | Data theft | Keychain/Keystore, encrypt |
| 77 | Insecure Mobile Transmission | HTTP, cert failures | Traffic interception | TLS, cert pinning |
| 78 | Insecure Mobile APIs | Missing auth/validation | Data exposure | OAuth/JWT, validation |
| 79 | App Reverse Engineering | Hardcoded creds | Credential theft | Obfuscation, RASP |
| 80 | IoT Management Issues | Weak auth, no TLS | Device takeover | Strong auth, TLS |
| 81 | Weak IoT Authentication | Default passwords | Unauthorized access | Unique creds, MFA |
| 82 | IoT Vulnerabilities | Design flaws, old firmware | Botnet recruitment | Updates, segmentation |
| 83 | Smart Home Access | Insecure defaults | Privacy invasion | MFA, segmentation |
| 84 | IoT Privacy Issues | Excessive collection | Surveillance | Data minimization |
| # | Vulnerability | Root Cause | Impact | Mitigation |
|---|---|---|---|---|
| 89 | MIME Sniffing | Missing headers | XSS, spoofing | X-Content-Type-Options |
| 91 | CSP Bypass | Weak config | XSS despite CSP | Strict CSP, nonces |
| 92 | Inconsistent Validation | Decentralized logic | Control bypass | Centralized validation |
| 93 | Race Conditions | Missing sync | Privilege escalation | Proper locking |
| 94-95 | Business Logic Flaws | Missing validation | Financial fraud | Server-side validation |
| 96 | Account Enumeration | Different responses | Targeted attacks | Uniform responses |
| 98-99 | Unpatched Vulnerabilities | Patch delays | Zero-day exploitation | Patch management |
| 100 | Zero-Day Exploits | Unknown vulns | Unmitigated attacks | Defense in depth |
| Category | Vulnerability Numbers | Key Controls |
|---|---|---|
| Injection | 1-13 | Parameterized queries, input validation, output encoding |
| Authentication | 14-23, 85-86 | MFA, session management, account lockout |
| Data Exposure | 24-27 | Encryption at rest/transit, access controls, DLP |
| Misconfiguration | 28-36 | Secure defaults, hardening, patching |
| XML | 37-39, 65 | Disable external entities, limit expansion |
| Access Control | 40-44 | RBAC, least privilege, authorization checks |
| Deserialization | 45-47 | Avoid untrusted data, integrity validation |
| API Security | 48-51, 75 | OAuth, rate limiting, input validation |
| Communication | 52-55 | TLS 1.2+, certificate validation, HTTPS |
| Client-Side | 56-60 | CSP, X-Frame-Options, safe DOM |
| DoS | 61-65 | Rate limiting, DDoS protection, resource limits |
| SSRF | 66, 87-88 | URL whitelisting, egress filtering |
| Mobile/IoT | 76-84 | Encryption, authentication, secure storage |
| Business Logic | 74, 92-97 | Threat modeling, logic testing |
| Zero-Day | 98-100 | Defense in depth, threat intelligence |
Content-Security-Policy: default-src 'self'; script-src 'self'
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=31536000; includeSubDomains
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: geolocation=(), microphone=()| OWASP 2021 | Related Vulnerabilities |
|---|---|
| A01: Broken Access Control | 40-44, 23, 74 |
| A02: Cryptographic Failures | 24-25, 53-55 |
| A03: Injection | 1-13, 37-39 |
| A04: Insecure Design | 74, 92-97 |
| A05: Security Misconfiguration | 26-36 |
| A06: Vulnerable Components | 34, 98-100 |
| A07: Auth Failures | 14-23, 85-86 |
| A08: Data Integrity | 45-47 |
| A09: Logging Failures | 73 |
| A10: SSRF | 66, 87-88 |
| Challenge | Solution |
|---|---|
| False positives in scanning | Manual verification, contextual analysis |
| Business logic flaws missed | Manual testing, threat modeling, abuse case analysis |
| Encrypted traffic analysis | Proxy configuration, certificate installation |
| WAF blocking tests | Rate adjustment, IP rotation, payload encoding |
| Session handling issues | Cookie management, authentication state tracking |
| API discovery | Swagger/OpenAPI enumeration, traffic analysis |
| Vulnerability Type | Verification Approach |
|---|---|
| Injection | Payload testing with encoded variants |
| XSS | Alert boxes, cookie access, DOM inspection |
| CSRF | Cross-origin form submission testing |
| SSRF | Out-of-band DNS/HTTP callbacks |
| XXE | External entity with controlled server |
| Access Control | Horizontal/vertical privilege testing |
| Authentication | Credential rotation, session analysis |
© zebbern, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/top-web-vulnerabilities of zebbern/claude-code-guide.
Open the folder on GitHubat commit e62775c
We found 24 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 8 other GitHub owners. This page covers the copy in zebbern/claude-code-guide, which our catalogue first saw on October 7, 2026.
Top Web Vulnerabilities next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Top Web Vulnerabilities this skillzebbern/claude-code-guide | 4.7k | 8 repos | ~6.1k | Automated safety check: Pass | MIT | |
| Security And Hardeningpenpot/penpot | 61k | 6 repos | ~4.7k | Automated safety check: Notes | MPL-2.0 | |
| Security Auditoreigent-ai/eigent | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | |
| Security Reviewjewbetcha/opentrace | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT | |
| Strix Code Vulnerability Scanusestrix/strix | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None |
penpot/penpot
Hardens code against vulnerabilities. An agent skill from penpot/penpot.
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
usestrix/strix
Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
usestrix/strix
Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.
zebbern/claude-code-guide
Analyze codebases and automatically generate architecture diagrams, flowcharts, and org charts.
zebbern/claude-code-guide
This skill should be used when setting up, auditing, or enforcing internationalization/localization in UI codebases (React/TS, i18next or similar, JSON locales), including installing/configuring the…
zebbern/claude-code-guide
Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.
zebbern/claude-code-guide
Generate publication-quality PNG chart images from data, supporting line, bar, area, candlestick, pie, and heatmap charts.
zebbern/claude-code-guide
Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.
zebbern/claude-code-guide
This skill should be used when the user asks to "create bash scripts", "automate Linux tasks", "monitor system resources", "backup files", "manage users", or "write production shell scripts".
Categories
This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks"…. Top Web Vulnerabilities is an agent skill from zebbern/claude-code-guide. This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks", "review access control weaknesses", "analyze API security issues", "assess security misconfigurations", "understand client-side vulnerabilities", "examine mobile and IoT security flaws", or "reference the OWASP-aligned vulnerability taxonomy".
Top Web Vulnerabilities fits situations like: asks to identify web application vulnerabilities; explain common security flaws; understand vulnerability categories; learn about injection attacks.
Run `npx skills add zebbern/claude-code-guide --skill top-web-vulnerabilities -a claude-code`. Or copy the skill folder (skills/top-web-vulnerabilities in zebbern/claude-code-guide) into .claude/skills/top-web-vulnerabilities in your project. Claude Code loads it when a task matches its description.
Run `npx skills add zebbern/claude-code-guide --skill top-web-vulnerabilities -a codex`. Or copy the skill folder (skills/top-web-vulnerabilities in zebbern/claude-code-guide) into .agents/skills/top-web-vulnerabilities in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zebbern/claude-code-guide --skill top-web-vulnerabilities -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/top-web-vulnerabilities, .gemini/skills/top-web-vulnerabilities, .github/skills/top-web-vulnerabilities and .opencode/skills/top-web-vulnerabilities in your project.
SKILL.md names no scripts, command-line tools or credentials: Top Web Vulnerabilities is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Top Web Vulnerabilities is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.1k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Top Web Vulnerabilities: Security And Hardening (penpot/penpot, 61k stars), Security Auditor (eigent-ai/eigent, 15k stars), Security Review (jewbetcha/opentrace, 116 stars) and Strix Code Vulnerability Scan (usestrix/strix, 67k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
zebbern (a GitHub user) maintains it in zebbern/claude-code-guide, which has 4,650 GitHub stars. The repository holds 46 skills in this directory. The repository was last updated on October 8, 2026.
Source: zebbern/claude-code-guide on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.